nerdexam
Isaca

CRISC · Question #310

An organization's Internet-facing server was successfully attacked because the server did not have the latest security patches. The risk associated with poor patch management had been documented in th

Sign in or unlock CRISC to reveal the answer and full explanation for question #310. The question stem and answer options stay visible for context.

Submitted by kim_seoul· Apr 18, 2026Governance

Question

An organization's Internet-facing server was successfully attacked because the server did not have the latest security patches. The risk associated with poor patch management had been documented in the risk register and accepted. Who should be accountable for any related losses to the organization?

Options

  • ARisk owner
  • BIT risk manager
  • CServer administrator
  • DRisk practitioner

Unlock CRISC to see the answer

You've previewed enough free CRISC questions. Unlock CRISC for full answers, explanations, the timed quiz mode, progress tracking, and the master PDF. Question stem and options stay visible so you can still see what's on the exam.

Topics

#Risk ownership#Accountability#Risk acceptance#Risk management roles
Full CRISC Practice